Gitlab News Articles
Recent news articles refferecing the vendors vulnerabilities.
(TLP CLEAR) Weekly Vulnerabilities to Prioritize – September 17, 2026 - WaterISAC
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical...
2 weeks ago
CISA Warns of Active Exploitation of Critical GitLab Flaw
CISA warns attackers are exploiting a critical GitLab flaw that exposes server files, credentials and development pipelines. Learn how to respond.
2 weeks ago
GitLab's Perfect-Score Flaw Exposes Servers to Unauthenticated File Theft as CISA Sounds Alarm
CISA added CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab, to its KEV catalog after confirmed exploitation. The bug lets unauthenticated attackers read arbitrary files via the commits API. Self-managed users must patch versions before 19.1.8, 19.2.6, and 19.3.2 immediately.
2 weeks ago
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
2 weeks ago
CISA: Hackers now exploit max severity GitLab flaw in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.
2 weeks ago
GitLab's Worst-Rated Vulnerability Is Already Being Exploited - IT Security News
GitLab on September 10 shipped emergency patches for a maximum-severity vulnerability that lets unauthenticated attackers read arbitrary files off a server and by the following morning, attackers were already...
2 weeks ago
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks - IT Security News
2026-09-12 07:09 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities...
3 weeks ago
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
CISA has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
3 weeks ago

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
3 weeks ago
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825.
3 weeks ago
GitLab Vulnerability Exploited One Day After Disclosure
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public disclosure.
3 weeks ago
Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
GitLab admins are urged to patch CVE-2026-19478 as attackers exploit the critical unauthenticated code injection flaw.I prefer this response

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - SwapUpdate
Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - NewsBreak
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in
Critical GitLab Flaw Exploited Shortly After Disclosure
Hackers started exploiting CVE-2026-19478, a critical, unauthenticated GitLab vulnerability, shortly after public disclosure.
GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability | eSecurity Planet
GitLab patched a critical GraphQL flaw as researchers observed exploitation attempts.
GitLab's Out-of-Band Patch Exposes Lingering GraphQL Risks in Self-Managed DevOps Pipelines
GitLab issued an emergency patch on August 17, 2026 for CVE-2026-19478, a critical GraphQL code injection flaw (CVSS 9.4) allowing unauthenticated attackers to modify or delete public projects under certain conditions. Self-managed instances from version 18.2 onward require immediate upgrades to 19....
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.
GitLab Emergency Patch: Third GraphQL Flaw of 2026 Lets Unauthenticated Attackers Delete Projects
GitLab vulnerability CVE-2026-19478 carries a CVSS 9.4 rating, letting unauthenticated attackers remotely delete or modify public projects with no login required. An emergency patch released August
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) - Help Net Security
GitLab has patched a critical, unauthenticated code injection flaw (CVE-2026-19478) that let attackers delete public projects and user data.
GitLab Patches Critical Code Injection Vulnerability
GitLab has patched CVE-2026-19478, a critical code injection vulnerability that can be exploited without authentication.
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab patches CVE-2026-19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data
CVE-2025-6948 | GitLab Community Edition/Enterprise Edition up to 17.11.5/18.0.3/18.1.1 cross site scripting (Issue 552616)
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.11.5/18.0.3/18.1.1 and classified as problematic. Affected by this vulnerability is an unknown functional…